ciso.diy
Azure Cloud Infrastructure Posture Kit preview
Compliance AzureEntra IDcloud securityKey Vault

Azure Cloud Infrastructure Posture Kit

One compromised identity reached Key Vault, Storage and Virtual Machines in minutes, in a chain Microsoft's own security team documented in 2026. Azure's dominant risk is identity, not raw exposure, and this kit is shaped for it: Key Vault and Storage weighted highest, both the CIS Azure and Microsoft Cloud Security Benchmarks cited, and no re-run of the Entra ID review M365-01 already did. Second of the three-cloud trilogy on one scoring scale.

What this actually gives you

  • One compromised identity read dozens of Key Vault secrets in four minutes, then minted Storage SAS tokens and backdoored VMs — a chain Microsoft's own security team documented in 2026. No exploit; one identity and everything it could reach.
  • Azure's dominant risk is identity, not raw exposure. 64% of scanned accounts had a public service — lower than AWS — but Azure leads all three clouds in misconfigured services, and Entra ID is the same plane your M365 kit already assessed.
  • This kit does not re-run the Entra ID review. Where M365-01 or OKTA-01 has assessed the shared tenant, file 02 scores only the Azure-specific delta. A buyer running the full set does not pay twice.
  • Key Vault and Storage are weighted highest. 61% of organisations have exposed secrets; the legacy access-policy model is still common; and legacy Storage accounts predating the 2023 default change commonly remain public.
  • Two switches would have caught the anchor incident — Key Vault diagnostics and Storage diagnostics — and both are off by default. File 06 asks that question of every row. Both the CIS Azure and Microsoft Cloud Security Benchmarks are cited in file 04.

Microsoft's own security team watched it happen. In a chain documented in May 2026, a single compromised identity was used to read dozens of secrets from Azure Key Vault — database connection strings among them — in four minutes. The attacker then abused Storage account key-listing to mint Shared Access Signature tokens and exfiltrated data over several days, and separately used the VM access extension to create backdoor administrator accounts on Virtual Machines. No exotic exploit. One identity, and every downstream Azure service it could reach. A separate 2026 incident exported millions of directory records across nine companies through Microsoft's own APIs, using stolen employee credentials from infostealer malware and no CVE at all.

Azure's risk shape differs in kind from AWS's. The same 2026 index built from live configuration data found 64% of Azure accounts had a publicly exposed service — lower than AWS's 76% — but Azure leads all three clouds in the misconfigured-services category, and its dominant driver is identity. Azure's security model is built around Entra ID far more centrally than AWS IAM or Google's Cloud Identity, so an Entra ID gap does not just affect Azure resources: it is frequently the same identity plane the M365 Security Posture Kit and, where in use, the Okta kit already assess.

So this kit deliberately does not repeat them. Unlike every other kit in the series, the identity module here is scoped to the Azure-specific gaps — RBAC scoping, service-principal credential hygiene, directory-read permission scope, bulk Graph export — where the tenant has already had its Conditional Access and MFA review. The Subscription Structure tab records whether that review has been done; if not, the module runs in full. A buyer running the whole posture set does not pay twice for the same identity assessment.

Key Vault is the surface this kit weights highest, and the data says why. 61% of organisations have exposed secrets, a documented Key Vault Contributor privilege-escalation path existed into late 2024, and the legacy access-policy permission model is still common. Public network access, the access-policy-versus-RBAC choice, bulk-secret-read alerting and rotation cadence each get their own row. Storage is second: public blob access has been off by default since late 2023, but legacy Storage accounts that predate the change commonly remain exposed.

Scored against both benchmarks. The CIS Microsoft Azure Foundations Benchmark and the Microsoft Cloud Security Benchmark — Microsoft's own successor to the Azure Security Benchmark — are cited together, with references per row, rather than picking one.

The detection finding is two switches. File 06 asks of every log source not just whether it is on by default but whether it would have caught the anchor incident. Key Vault diagnostic logs and Storage diagnostic logs are the two that would have, and both are off until someone turns them on.

What you get

01 Assessment Methodology (DOCX) — how Azure's risk shape differs, the anchor attack chain, the non-duplication rule, the five modules, run order, cross-links and assumptions.

02 Identity & Access Review Workbook (XLSX) — Conditional Access & MFA (or the delta), Privileged Role Management (Global Administrator and Owner counts, PIM activation, review cadence), Azure RBAC & Service Principals (assignments scoped to resource groups, custom-role review, client-secret and certificate rotation) and Directory & Guest Access (directory-read scope for standard users, guest review, bulk Graph export monitoring), rolling into one identity posture score.

03 Blast Radius Scoring Tool (XLSX) — the flagship module. Record the Subscription Structure first — single subscription or Management Groups, identity assessment status, Key Vault permission model — then answer the control questions across Key Vault exposure, Storage account exposure (AllowBlobPublicAccess off at the account level, key access restricted in favour of Entra ID), compute & network, and management-plane monitoring — the four surfaces Microsoft's own remediation guidance for the anchor incident names. One score, a band on the same bands as every posture kit, and a closure list ranked by risk-weighted points.

04 CIS / MCSB-Aligned Hardening Checklist (XLSX) — Identity & Privileged Access, Storage & Key Vault, Networking & Compute (no 0.0.0.0/0 to management ports, NSG flow logs, encrypted managed disks with just-in-time access, Bastion over public RDP and SSH) and Monitoring & Logging (diagnostic logging everywhere it is supported, Defender for Cloud with Secure Score reviewed, Sentinel or a SIEM ingesting the Activity Log, Key Vault bulk-access and mass-deletion alerts), scored gap-to-target with a hardening percentage per family.

05 Data Governance Review (DOCX) — Storage account and managed-disk encryption with customer-managed keys where fine-grained control is needed, Key Vault rotation policy and the permission-model choice, and data classification coverage.

06 Detection Readiness Matrix (XLSX) — Entra ID sign-in and audit logs, Key Vault diagnostics, Storage diagnostics, the Azure Activity Log, Policy compliance and Defender recommendations, each row stating whether it is on by default and whether it would have caught the anchor chain.

07 Executive Summary Template (DOCX) — one page: the four module scores, top five findings, plain-language meaning, remediation timeline, and the note to run the AWS and Google Cloud kits alongside for a multi-cloud estate and to cross-reference the M365 kit where Entra ID is shared.

azr01.json — scoring bands, surfaces, subscription-structure components, the two benchmarks and the module map.

A worked example throughout. Alderway Logistics, a fictional logistics company with a single Azure subscription and an Entra ID tenant shared with its Microsoft 365 estate, whose newer Key Vaults use private endpoints while two legacy ones still allow public network access.

Where it sits. The AWS Cloud Infrastructure Posture Kit is the trilogy sibling built first, and the Google Cloud Platform Posture Kit completes it, all on the same bands; the trilogy is cheaper than buying all three. The M365 and Okta kits assess the identity plane this subscription shares. An AKS cluster inherits this subscription's IAM risk — the Docker & Kubernetes Security Posture Kit follows the chain from the pod to here. The GitHub / GitLab Security Posture Kit covers the pipeline that holds the credentials. The IR Runbook Library is the response layer; run it against a vendor's subscription with the TPRM Program Kit; hand file 07 to the Director's Cyber Oversight Kit.

Written against Azure and Entra ID service names, defaults, published statistics and incident reporting, the CIS Azure Foundations Benchmark and the Microsoft Cloud Security Benchmark as of Q3 2026, marked verify. Benchmark references are section mappings to a condensed control set. Not a replacement for Defender for Cloud — the posture and prioritisation layer above it. Not a penetration test. Scores are a prioritisation aid, not a certification, an audit opinion or an insurance-underwriting determination. Not legal advice.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-09
Pages 7